1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
|
Candidate: CVE-2004-0814
References:
BUGTRAQ:20041020 CVE-2004-0814: Linux terminal layer races
URL:http://www.securityfocus.com/archive/1/379005
CONFIRM:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=131672
CONFIRM:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=133110
FEDORA:FLSA:2336
URL:https://bugzilla.fedora.us/show_bug.cgi?id=2336
MANDRAKE:MDKSA-2005:022
URL:http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:022
BUGTRAQ:20041214 [USN-38-1] Linux kernel vulnerabilities
URL:http://marc.theaimsgroup.com/?l=bugtraq&m=110306397320336&w=2
BID:11491
URL:http://www.securityfocus.com/bid/11491
BID:11492
URL:http://www.securityfocus.com/bid/11492
XF:linux-tiocsetd-race-condition(17816)
URL:http://xforce.iss.net/xforce/xfdb/17816
Description:
Multiple race conditions in the terminal layer in Linux 2.4.x, and 2.6.x
before 2.6.9, allow (1) local users to obtain portions of kernel data via a
TIOCSETD ioctl call to a terminal interface that is being accessed by another
thread, or (2) remote attackers to cause a denial of service (panic) by
switching from console to PPP line discipline, then quickly sending data that
is received during the switch.
Notes:
Bugs:
upstream: released (2.6.9)
linux-2.6: N/A
2.6.8-sarge-security: released (2.6.8-8) [tty-locking-fixes.dpatch, tty-locking-fixes2.dpatch, tty-locking-fixes3.dpatch, tty-locking-fixes4.dpatch, tty-locking-fixes5.dpatch, tty-locking-fixes6.dpatch, tty-locking-fixes7.dpatch, tty-locking-fixes8.dpatch]
2.4.27-sarge-security: released (2.4.27-7) [093_tty_lockup.diff, 093_tty_lockup-2.diff, 115_tty_lockup-3.diff, 093-tty_lockup-3.diff]
2.4.19-woody-security:
2.4.18-woody-security:
2.4.17-woody-security:
2.4.16-woody-security:
2.4.17-woody-security-hppa:
2.4.17-woody-security-ia64:
2.4.18-woody-security-hppa:
|